<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 21:32:05 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-355457</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-355457</link>
      <description>EUVD-2026-355457</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-355457</guid>
    </item>
    <item>
      <title>fkie_cve-2026-50139</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50139</link>
      <description>&lt;p&gt;goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token&amp;#39;s `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot, all pass the check, and all are served — exceeding the operator&amp;#39;s intended cap. Version 2.1.0 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token&amp;#39;s `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot, all pass the check, and all are served — exceeding the operator&amp;#39;s intended cap. Version 2.1.0 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-50139</guid>
    </item>
    <item>
      <title>GHSA-j48m-h7xq-2xpj — goshs: Share-link ?token=… redemption races past download limit</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j48m-h7xq-2xpj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: goshs.de/goshs/v2&lt;/p&gt;
&lt;p&gt;# Share-link `?token=…` redemption races past download limit&lt;/p&gt;
&lt;p&gt;**Ecosystem:** Go
**Package:** `goshs.de/goshs/v2` (`github.com/patrickhener/goshs`)
**Affected:** `&amp;lt;= v2.0.9` (every release that shipped the share-link feature)&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`ShareHandler` reads the share token&amp;#39;s `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot, all pass the check, and all are served — exceeding the operator&amp;#39;s intended cap.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;[`httpserver/handler.go:968-1018`](https://github.com/patrickhener/goshs/blob/v2.0.9/httpserver/handler.go#L968-L1018):&lt;/p&gt;
&lt;p&gt;```go
fs.sharedLinksMu.RLock()
entry, ok := fs.SharedLinks[token]
fs.sharedLinksMu.RUnlock()                       // &amp;lt;-- released here&lt;/p&gt;
&lt;p&gt;if entry.DownloadLimit &amp;gt; 0 || entry.DownloadLimit == -1 {
    // ...serve file...                          // &amp;lt;-- whole transfer happens unlocked
}&lt;/p&gt;
&lt;p&gt;fs.sharedLinksMu.Lock()                          // &amp;lt;-- re-acquired only now
current.Downloaded++
if current.Downloaded &amp;gt;= current.DownloadLimit { delete(fs.SharedLinks, token) }
fs.sharedLinksMu.Unlock()
```&lt;/p&gt;
&lt;p&gt;Between line 978 (`RUnlock`) and line 1008 (`Lock`), any number of goroutines can interleave and each observes the same pre-increment limit.&lt;/p&gt;
&lt;p&gt;## Proof of concept&lt;/p&gt;
&lt;p&gt;```bash
goshs -p 18000 -d /tmp/r -b admin:pw &amp;amp;
echo data &amp;gt; /tmp/r/f.txt&lt;/p&gt;
&lt;p&gt;# operator issues a one-shot share
SHARE=$(curl -su admin:pw &amp;#34;http://localhost:1…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: goshs.de/goshs/v2&lt;/p&gt;
&lt;p&gt;# Share-link `?token=…` redemption races past download limit&lt;/p&gt;
&lt;p&gt;**Ecosystem:** Go
**Package:** `goshs.de/goshs/v2` (`github.com/patrickhener/goshs`)
**Affected:** `&amp;lt;= v2.0.9` (every release that shipped the share-link feature)&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`ShareHandler` reads the share token&amp;#39;s `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot, all pass the check, and all are served — exceeding the operator&amp;#39;s intended cap.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;[`httpserver/handler.go:968-1018`](https://github.com/patrickhener/goshs/blob/v2.0.9/httpserver/handler.go#L968-L1018):&lt;/p&gt;
&lt;p&gt;```go
fs.sharedLinksMu.RLock()
entry, ok := fs.SharedLinks[token]
fs.sharedLinksMu.RUnlock()                       // &amp;lt;-- released here&lt;/p&gt;
&lt;p&gt;if entry.DownloadLimit &amp;gt; 0 || entry.DownloadLimit == -1 {
    // ...serve file...                          // &amp;lt;-- whole transfer happens unlocked
}&lt;/p&gt;
&lt;p&gt;fs.sharedLinksMu.Lock()                          // &amp;lt;-- re-acquired only now
current.Downloaded++
if current.Downloaded &amp;gt;= current.DownloadLimit { delete(fs.SharedLinks, token) }
fs.sharedLinksMu.Unlock()
```&lt;/p&gt;
&lt;p&gt;Between line 978 (`RUnlock`) and line 1008 (`Lock`), any number of goroutines can interleave and each observes the same pre-increment limit.&lt;/p&gt;
&lt;p&gt;## Proof of concept&lt;/p&gt;
&lt;p&gt;```bash
goshs -p 18000 -d /tmp/r -b admin:pw &amp;amp;
echo data &amp;gt; /tmp/r/f.txt&lt;/p&gt;
&lt;p&gt;# operator issues a one-shot share
SHARE=$(curl -su admin:pw &amp;#34;http://localhost:1…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j48m-h7xq-2xpj</guid>
    </item>
  </channel>
</rss>
